th the fu futur ure is is he here e
play

Th The Fu Futur ure Is Is He Here e - Mode dern rn Attack - PowerPoint PPT Presentation

Th The Fu Futur ure Is Is He Here e - Mode dern rn Attack ttack Sur urface ace On On Au Automotiv omotive Lior Yaari 28/11/2019 Techy Trainer at DeepSec 7 Years In Cyber Security Vulnerability Researcher Sec-Dev CS Teacher


  1. Th The Fu Futur ure Is Is He Here e - Mode dern rn Attack ttack Sur urface ace On On Au Automotiv omotive Lior Yaari 28/11/2019

  2. Techy Trainer at DeepSec 7 Years In Cyber Security Vulnerability Researcher Sec-Dev CS Teacher Consultant Casual Cool Born In Studying Jerusalem German Hobby

  3. Building Security End to End Breaking through Bypassing ECU Products Security Testing the cloud or factory protections IDS IPS Automotive SOC Vehicle Security Research Prevention Concepts

  4. Disclaimer As part of our job with CYMOTIVE we are working closely with several automotive companies and because of that many of our findings are under NDA. We will not include ANY customer names and real issues which can cause any harm and focus more on the tech side * All photos in this presentation are from open sources found on the internet

  5. Progress Bar • Who I Am • Automotive Past & Future • Connected Technologies • Centralized Management

  6. Automotive Main Trends LiDAR NFC SLAM Wifi V2X PLC GPS Thermo Bluetooth Sonar 4G

  7. Who talks to my car? Year 2005~

  8. Who talks to my car? Bluetooth, Wifi Year 2015~

  9. Who talks to my car? OTA Cloud RF,BLE Year 2025~

  10. What does it imply?

  11. Changes CAN Bus Ethernet Mechanical Engineer Software Developer

  12. New Demands Vehicle Clouds Growing IT Department Tons of Infosec Jobs

  13. Some Terminology Original Equipment Manufacturer (OEM)

  14. Some Terminology Electronic Control Unit (ECU) Door Info Engine Radio Gateway Nav Airbag Body ABS Door Diag

  15. Some Terminology Infotainment (Information + Entertainment)

  16. Progress Bar • Who We Are • Automotive Past & Future • Connected Technologies • Centralized Management

  17. The new fashion in vehicle IoT are “Aftermarket Solutions” Which are also the solution for hackers

  18. Aftermarket Solutions Chainway TSP Viper Smart Start Samsung MYCAR Vinli OBD-II Drone Mobile Engie

  19. Hacking the: Server, Phone, Dongle -> Dongle Server Hacking the car

  20. Keyless Entry =< Car Sharing

  21. By Continental https://www.youtube.com/watch?v=vdnrr5i4naE

  22. Car2Go App MYCAR App - Found by Jmaxxz

  23. The Bluetooth Problem Hell2CAP (Cymotive) Infotainment, CVE-2018-20378 Dongles, Keys are all KNOB (SUTD) Bluetooth connected CVE-2019-9506 BleedingBit (Armis) CVE-2018-16986 CVE-2018-7080

  24. Hell2CAP Found by Barak Caspi at Cymotive State machine bug in BlueSDK L2CAP (~100 Million Devices) We Are Here

  25. L2CAP Channel Multiplexing PSM – “Protocol ID” L2CAP_Connect(PSM=0x1)

  26. L2CAP Channel Multiplexing PSM – “Protocol ID” DCID – channel identifier L2CAP_Connect(PSM=0x1) L2CAP_ConnectResp(DCID=0x41)

  27. L2CAP Channel Multiplexing PSM – “Protocol ID” DCID – channel identifier L2CAP_Connect(PSM=0x1) L2CAP_ConnectResp(DCID=0x41) L2CAP_ConfReq(DCID=0x41, …)

  28. L2CAP Configuration Can config: MTU, Timeout and more Minimal Bluetooth MTU is 48 - Bluetooth Specification Version 3.0 + HS [Vol 3]

  29. L2CAP Configuration Save MTU Pseudo code Set Invalid Check Size On Fail

  30. L2CAP Configuration Connect Channel 0x41 Valid – Yes MTU – 0x500

  31. L2CAP Configuration Connect L2CAP_ConfReq(DCID=0x41, Channel 0x41 MTU=0x200) Valid – Yes MTU – 0x200 L2CAP_ConfResp(DCID=0x41, SUCCESS)

  32. L2CAP Configuration Connect L2CAP_ConfReq(DCID=0x41, Channel 0x41 MTU=0x10) Valid – No MTU – 0x10 L2CAP_ConfResp(DCID=0x41, INVALID)

  33. Hell2CAP Red flag – Values is stored (4) than checked (5) Can we restore channel to be valid?

  34. Hell2CAP Red flag – Values is stored (4) than checked (5) Can we restore channel to be valid? ConfigRequest Channel Invalid. Channel Valid ConfigRequest (FlushTimeout (MTU = 20) ch.MTU = 20 ch.MTU = 20 = 0x1337)

  35. Hell2CAP On upper layer – SDP there is fragmentation code MTU from L2CAP, we control it

  36. Hell2CAP On upper layer – SDP there is fragmentation code MTU = 48 -> availableSizeForFragment = 48 – 9 = 39 MTU = 8 -> availableSizeForFragment = 8 – 9 = 0xFFFF Integer underflow

  37. Hell2CAP Set Low Integer Buffer Profit MTU Underflow Overflow

  38. The problem with Bluetooth is that it is not the only problem V2X

  39. V2X – Vehicle to X

  40. By Autotalks https://www.youtube.com/watch?v=RRDiDPnv_b4

  41. V2X payload is ASN.1 based

  42. A fake V2X module could Create Force Generate False Emergency False Alarms Traffic Breaks

  43. Charging Evolution

  44. Charging PLC EVSE – Electric Vehicle Supply Equipment PEV – Plug-in Electric Vehicle EVSE PEV

  45. Charging PLC PLC – Power Line Communication EVSE PEV

  46. XML- Charging Protocol Stack EXI V2GTP TLS SDP Vendor SLAC UDP TCP Specific HPGP IPv6 Wired / Ethernet

  47. XML- XML Parsers Vulns EXI V2GTP Header Edge Cases TLS SDP Vendor SLAC UDP TCP Specific HPGP IPv6 Wired / Ethernet

  48. XML- XML Parsers Vulns EXI V2GTP Header Edge Cases TLS SDP Vendor SLAC UDP TCP VxWorks TCP/IP Stack CVEs by Specific Armis Labs URGENT/11 (19.7.2019): HPGP IPv6 IP RCE: CVE-2019-12256 TCP RCE: CVE-2019-12255, CVE-2019-12260, CVE-2019- Wired / Ethernet 12261, CVE-2019-12263

  49. EVSE! Use Buffer Overflow!

  50. Hackers Benefits Charge your credit card and not your car Hack other ECUs from PEV PEV EVSE

  51. Progress Bar • Who I Am • Automotive Past & Future • Connected Technologies • Centralized Management

  52. Hackers Benefits Vehicle EVSEs are Clouds all cloud connected

  53. The Magical The Vehicle Place Where Everything Is Cloud Possible (For a Hacker)

  54. The Vehicle Cloud Juicy Stuff Normal Stuff Private Information GPS Coordinates Credit Cards Remote Unlock OEM Secrets OTA Updates

  55. The Vehicle Futuristic Stuff Cloud Centralized Control for Shared Transportation Next-Gen Police The cloud is the limit…

  56. OTA – Over The Air Most modern cars receive software updates with 4G connection to the OEM servers

  57. The Vehicle Cloud Update Update Update Update Update

  58. The Vehicle Cloud Update Update Update Update Update

  59. ST STOP! OP! Pay 5000$ to unlock this car

  60. 4/11/2019

  61. The bright side OEMs invest Connected immense efforts autonomous in cyber security would be really great

  62. TL;DR Risks Opportunities Everything Is Connected Less Accidents New Attack Vectors – Life Changing BT, Wifi, NFC, V2X, PLC Technologies

  63. Ask Me Anything Lior.yaari@cymotive.com Lior@imperium-sec.com Twitter: @lior_yaari

  64. Hell2CAP Found by Barak Caspi at Cymotive State machine bug in BlueSDK L2CAP (~100 Million Devices) We Are Here

  65. L2CAP Channel Multiplexing PSM – “Protocol ID” L2CAP_Connect(PSM=0x1)

  66. L2CAP Channel Multiplexing PSM – “Protocol ID” DCID – channel identifier L2CAP_Connect(PSM=0x1) L2CAP_ConnectResp(DCID=0x41)

  67. L2CAP Channel Multiplexing PSM – “Protocol ID” DCID – channel identifier L2CAP_Connect(PSM=0x1) L2CAP_ConnectResp(DCID=0x41) L2CAP_ConfReq(DCID=0x41, …)

  68. L2CAP Configuration Can config: MTU, Timeout and more Minimal Bluetooth MTU is 48 - Bluetooth Specification Version 3.0 + HS [Vol 3]

  69. L2CAP Configuration Save MTU Pseudo code Set Invalid Check Size On Fail

  70. L2CAP Configuration Connect Channel 0x41 Valid – Yes MTU – 0x500

  71. L2CAP Configuration Connect L2CAP_ConfReq(DCID=0x41, Channel 0x41 MTU=0x200) Valid – Yes MTU – 0x200 L2CAP_ConfResp(DCID=0x41, SUCCESS)

  72. L2CAP Configuration Connect L2CAP_ConfReq(DCID=0x41, Channel 0x41 MTU=0x10) Valid – No MTU – 0x10 L2CAP_ConfResp(DCID=0x41, INVALID)

  73. Hell2CAP Red flag – Values is stored (4) than checked (5) Can we restore channel to be valid?

  74. Hell2CAP Red flag – Values is stored (4) than checked (5) Can we restore channel to be valid? ConfigRequest Channel Invalid. Channel Valid ConfigRequest (FlushTimeout (MTU = 20) ch.MTU = 20 ch.MTU = 20 = 0x1337)

  75. Hell2CAP On upper layer – SDP there is fragmentation code MTU from L2CAP, we control it

  76. Hell2CAP On upper layer – SDP there is fragmentation code MTU = 48 -> availableSizeForFragment = 48 – 9 = 39 MTU = 8 -> availableSizeForFragment = 8 – 9 = 0xFFFF Integer underflow

  77. Hell2CAP Set Low Integer Buffer Profit MTU Underflow Overflow

  78. Ask Me Anything Lior.yaari@cymotive.com Lior@imperium-sec.com Twitter: @lior_yaari

Recommend


More recommend